Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 57f4597c8c57bf72…

MALICIOUS

Office (OLE) / .XLS

2.5 KB First seen: 2026-04-13
MD5: c21f8bfa8a5fdeefbb1618abcbce0308 SHA-1: 78b6deb3f6b02c8898d1dc6209d8daf8c1b4416b SHA-256: 57f4597c8c57bf72047b12adba0ba8eee1e1bf7bf97a35e7798f2e2f3dca83b7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution T1566.001 Phishing: Spearphishing Attachment

The sample is an OLE file that fired a critical heuristic for CVE-2026-21509, indicating a Protected View bypass. The embedded URL suggests a potential download or redirection to a malicious resource. The attack pattern is likely a phishing lure designed to trick the user into opening the malicious file and triggering the exploit.

Heuristics 1

  • OLE/COM security bypass — CVE-2026-21509 (Killbit/Protected View bypass) critical CVE related CVE_2026_21509
    OLE/COM security bypass — CVE-2026-21509 (Killbit/Protected View bypass)